PT-2026-94307 · Npm · Vm2
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
vm2 versions 3.11.4 through 3.11.6
Description
A sandbox escape exists when the
NodeVM constructor incorrectly validates the require configuration. By providing an array-shaped value to the require parameter while nesting is enabled, the hasRealRequireConfig check is bypassed. This allows the makeResolverFromLegacyOptions() function to return a resolver that grants access to the host vm2 module. An attacker can then instantiate an inner NodeVM with a custom builtin allowlist, such as child process, to execute arbitrary commands with the privileges of the host Node.js process, bypassing outer builtin restrictions.Recommendations
Update to version 3.11.7.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vm2